Burr & Forman LLP
ent_019e10cee803eda4ae4da8e2e099197c
Disclosures
12
State AG · HHS OCR · 9 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
28,616
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Burr & Forman LLP
- Normalized
- burr forman— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900YH7R3PB3E2HD04
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (12)newest first
- Massachusetts State AGas victim2024-07-22
Burr & Forman LLP reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-07-22. 7 Massachusetts residents were affected.
- Maine State AGas victim2024-07-22
Burr & Forman LLP reported a data breach where an unauthorized actor accessed systems on Sept 30, 2023, discovered Oct 23, 2023. Affected data included names, SSNs, driver's licenses, medical coding info, and insurance details. 28,616 individuals affected, including 3 Maine residents. Notification sent July 16, 2024. FBI notified; IDX credit monitoring offered.
- New Hampshire State AGas victim2024-07-22
Burr & Forman LLP reported a data security incident to the New Hampshire Attorney General. An unauthorized actor gained access to systems on or about September 30, 2023, detected on October 23, 2023. Personal information of 1 NH resident was affected. The firm engaged cybersecurity experts, notified the FBI, and offered credit monitoring.
- Vermont State AGas victim2024-07-22
Burr & Forman LLP notified consumers of a data breach where an unauthorized actor accessed systems on September 30, 2023. The incident involved the exfiltration of personal information, including names. The firm engaged cybersecurity experts, notified the FBI, and offered credit monitoring services to affected individuals.
- Washington State AGas reporting2024-05-28
HealthFirst Urgent Care, PLLC disclosed a privacy incident to the Washington AG on May 28, 2024. Between Oct 1, 2023, and Apr 1, 2024, a workforce member used contractors without proper safeguards, exposing patient names, account numbers, CPT codes, and billing/payment data for 4,111 WA residents. Discovered Apr 10, 2024. No SSN or clinical data involved. Remediation included policy review and termination of involved parties.
- Maine State AGas victim2024-01-10
Burr & Forman LLP, a law firm, reported a data breach to the Maine Attorney General, stating that an external system breach (hacking) occurred and was discovered on October 23, 2023. The breach affected 2 Maine residents and compromised their names and Social Security numbers. The company began notifying affected individuals on January 9, 2024, and offered identity theft protection services.
- Vermont State AGas victim2024-01-10
Burr & Forman LLP notified consumers of a data security incident discovered on October 23, 2023, involving anomalous activity on a laptop. An unauthorized actor accessed documents containing names, SSNs, medical coding info, and insurance data. Burr & Forman engaged cybersecurity experts, notified the FBI, and offered 24 months of credit monitoring via IDX.
- Montana State AGas reporting2024-01-10
Burr & Forman LLP notified Montana residents of a data incident affecting Oceans Healthcare. On Oct 23, 2023, Burr & Forman detected anomalous activity on a laptop, leading to unauthorized access to PHI and PII (SSN, names). Notices sent Jan 9, 2024, offering 24 months of credit monitoring.
- Indiana State AGas victim2024-01-09
Burr & Forman LLP reported a data breach to the Indiana Attorney General. The breach occurred on 2023-09-30 and was reported on 2024-01-09. 32 Indiana residents were affected. 28,616 individuals affected in total.
- ALABAMAHHS OCRas victim2024-01-09
Burr & Forman LLP, an Alabama-based law firm acting as a HIPAA business associate, reported a ransomware incident on 2024-01-09 affecting protected health information of 19,893 individuals. PHI involved included names, dates of birth, Social Security numbers, claims and financial information, and treatment information, stored on a network server. The firm notified HHS, affected individuals, and the media; posted substitute notice on its website; offered complimentary credit monitoring and identity protection services; and implemented additional technical safeguards.
- Illinois State AGas victim2024-01-01
BURR & FORMAN LLP filed a data-breach notice with the Illinois Attorney General in January 2024 (case 24-01-013). The register records the breach as discovered on October 23, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas reporting2020-12-08
Dunn Investment Company experienced a ransomware attack on September 30, 2020. The incident affected a server containing personnel, payroll, and supplier information, including names, addresses, Social Security numbers, dates of birth, employee ID numbers, and in some cases bank account numbers and driver's license numbers. The company contained the intrusion and restored data from backups. One New Hampshire resident was affected. The company offered one year of complimentary identity protection services.